Security

Security headers: five lines that close common attacks

HSTS, nosniff, framing protection and Referrer-Policy: what each header does and how to enable it on your server.

Checked against sources: 30 September 2026

  • 5headers close common attacks
  • 180 daysHSTS minimum for Awe Check
  • 1 yeartypical HSTS period

Five headers

  • Strict-Transport-Security tells browsers to always use HTTPS, even when http:// was typed.
  • X-Content-Type-Options: nosniff stops the browser from guessing a file type.
  • X-Frame-Options or frame-ancestors keeps your site out of another page’s frame.
  • Referrer-Policy stops full page URLs leaking to other sites.
  • A hidden server version: a version number in headers tells attackers which vulnerabilities to try.

A ready set

In nginx that is the add_header directive and server_tokens off, in Apache Header always set and ServerTokens Prod. Hosting panels and Cloudflare have toggles for the same values.

Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
Referrer-Policy: strict-origin-when-cross-origin

Be careful with HSTS

First make sure every subdomain works over HTTPS and start with a short period: max-age=300. After a week set a year. Awe Check asks for at least 180 days.

Frequently asked

Do I also need a CSP?

It is stronger but harder: a wrong CSP breaks the site. Start with the five headers above and add CSP separately, checking the console.

Do headers affect SEO?

Not directly. But HTTPS and a stable, uncompromised site are part of the trust search engines build on.

Sources

Check your site

Awe Check shows in a minute which of this is broken on your site and calculates the possible fine.

Check a site